190 likes | 346 Views
Application Hosting Customer Workshop. November 2, 2010. David Updike, Acting Director National Computer Center. Welcome & Thank You. Thank you …..for taking the time to join us as we review NCC plans to Enhance EPA hosting technology and Improve NCC service delivery
E N D
Application Hosting Customer Workshop November 2, 2010 David Updike, Acting Director National Computer Center
Welcome & Thank You Thank you …..for taking the time to join us as we review NCC plans to Enhance EPA hosting technology and Improve NCC service delivery Thank you …..for providing your honest and candid feedback in these sessions Thank you…..for being our customer We appreciate the opportunity to work with and help you solve your hosting needs
EPA’s Cloud Targets • EPA & NCC are moving rapidly toward cloud services • Now— • Much of hosting already leveraging cloud technologies • You will learn more about that today • Within 2011 • Brokered external cloud services for some low sensitivity applications • Within 2012 • Private cloud services across four EPA data centers for EPA medium sensitivity applications • High availability and/or disaster recovery across EPA’s four primary data centers
Cloud Services & EPA CPICs • EPA will have a standard approach for engaging cloud services • OEI will develop the approach in 2011 • Customers will be engaged in the approach development • OEI will provide Agency standard language for CPICs to address cloud services integration
EPA Data Center Goals • Scalability • Availability • Reliability • Affordability • Maximize Virtualization • Minimize Carbon Footprint • Service Based & Automated
Network Optimization • Again—We’ve got our head in the cloud • WAN 2010 migration in progress • Cloud Services for • WAN Backbone • Edge Security • Increased bandwidth for many sites— & room to grow
Email Optimization Initiative • Moves email from approximately 200 servers distributed Agency-wide to approximately 20 servers in the four primary data centers • Establishes baseline infrastructure for integrated EPA private cloud in EPA’s four primary data centers • Migration complete in August 2011
Email Optimization Service Areas* Port Orchard, WA Seattle, WA Olympia, WA Anchorage, AK Chelmsford, MA Boston, MA Narragansett, RI Newport, OR Portland, OR Corvallis, OR Helena, MT Duluth, MN Grosse Ile, MI Ann Arbor, MI New York, NY Edison, NJ Philadelphia, PA Boise, ID Denver, CO NEIC, Lakewood CO Cincinnati, OH – Norwood, AWBERC Potomac Yard San Francisco, CA Region 5 (Chicago) Ft. Meade, MD Annapolis, MD Erlanger, KY Potomac Yard Federal Triangle Region 8 (Denver) Kansas City, KS RTP, NC Chapel Hill, NC Las Vegas, NV – UNLV RTP Ada, OK Athens, GA Atlanta, GA Montgomery, AL Dallas, TX - OER/COOP Gulf Breeze, FL Stennis Space Center, MS Puerto Rico *Initial plan subject to change
Email Optimization Objectives • Email Optimization will • Improve service delivery and provide a seamless experience regardless of organization or location within EPA • Improve performance and portability for remote workers • Control costs of email storage growth • Reduce environmental impact of Email hosting
Back on the Ground …. We Need to Focus Jointly on Integrating and Improving our Security Awareness & Response 13
The security threat is real Well organized and funded government and terrorist organizations are aggressively attacking commercial, federal and EPA IT resources to: Acquire confidential information Establish privileged access to government IT resources Commonly referred to as Advanced Persistent Threat (APT) Integrated Security Awareness and Response is required to ensure the continued protection of our information and infrastructure resources Integrated Security Awareness & Response 14
EPA must establish increasingly proactive, integrated and automated approaches to: Configuration management Security surveillance Incident response EPA applications and infrastructure must integrate with EPA security management platforms Integrated authentication and access control for applications and infrastructure Common log analysis platforms (ArcSight) Integrated IT management platforms for: System Configuration, Software Distribution and Vulnerability Management (BigFix) Desktop/Laptop & Server Security (Symantec Endpoint Protection) Integrated Security Awareness & Response 15
Integrated Security Awareness & Response • Partnership Involvement • All EPA Regions, Program Office Security Staff and Senior Information Officials (SIOs) asked to heighten security awareness and monitoring activities. • Increased operations security coordination within OTOP • EPA application owners must: • Establish baselines for expected and usual behavior • Continuously monitor and report unexpected or unusual behavior • No local connections to the Internet or other networks • EPA network communication must comply with Federal Trusted Internet Connection requirements • All EPA network communications, applications & devices must be visible to EPA’s Network Security and Operations Center (NSOC) monitoring systems
Log Reviews Roles and Responsibilities • For NCC hosted applications, NCC provides the audit log reviews and anomalous behavior reporting for all logs through the application platform • Application owners must define what is usual and unusual for their applications and alert CSIRC • This may require event logging within your custom application • Application owners who manage their own user authentication and access control are responsible for reviewing and alerting unauthorized access
Log Review Roles and Responsibilities NCC Hosted Audit/Log Category Site Hosted (internal org.) (external) Application Owner Responsibility Customer Application Customer Application Management User Access & Authentication WAM Application Platform Application Platform Management Server OS Server Application Owner Responsibility Application Owner Responsibility Management Management Server Storage Storage & Management Back - Up Network Network Management Facilities Computer Management Rooms Pg 1
Contacts: David Updike Acting Director, National Computer Center Updike.David@epa.gov 919-541-0780 Tim Thorpe, Acting Associate Director, National Computer Center Thorpe.Tim@epa.gov 919-541-0613 John Gibson Acting Security and Business Management Branch Chief, National Computer Center Gibson.John@epa.gov 919-541-0112